
hdrj3 (hdrj3) asked a question.
We are looking to protect a certain group of elevated accounts by enforcing MFA when they RDP to our servers but want to continue to allow any and all other accounts that currently have the ability to RDP to do so without MFA. We have enabled the Microsoft RDP MFA Application and installed the credential provider on a test server. After importing our directory, we assigned the Domain Users group to the Microsoft RDP (MFA) application as a catch-all for any accounts who have the ability to RDP to a server and have enforced MFA for that particular group we want to protect. This works just fine however, local accounts are not able to RDP and get the error "Multifactor Authentication Failed" when attempted. I've come across some Okta discussions suggesting to create an Okta account and assign it to the application with the login name hostname/localaccountname however, this didn't work when tried and additionally, would mean that we would have to create hundreds of these to account for each server's hostname. We even tried a single Okta account with the sign-in name .\localaccountname but this too didn't work.
Is there a way to make it so that local accounts can bypass the Okta MFA credential provider? We don't want local accounts to have anything to do with this Okta MFA for servers deployment.

Hello and Thank you for reaching out to the Okta Community!
I'm afraid that this currently is an "All-or-Nothing" type of implementation.
https://help.okta.com/en/prod/Content/Topics/Security/proc-mfa-win-creds-rdp-assign-users.htm
The documentation mentions that "All users who login to any machine that has the Credential Provider installed will need to be assigned to the Microsoft RDP (MFA) app. "
You could suggest an enhancement on the Okta Community page by going to the Community→ Ideas tab. Features suggested in our community are reviewed and can be voted and commented on by other members. High popularity will increase the likelihood of it being picked up by the Product Team and it being implemented.
More details here:
https://support.okta.com/help/s/blog/a674z000001cj7YAAQ/okta-ideas-faq?language=en_US
Have a great rest of the day!